Best practices for authorizing server actions
Unanswered
Saltwater Crocodile posted this in #help-forum
Saltwater CrocodileOP
Hi, I have a middleware in nextjs that authorizes users, and redirects them to the correct page if they try to access unauthorized pages.
If a logged out user tries to access any page aside from the login page they are redirected
if a normal user tries to access pages under
If an admin tries to access pages under
Inside my pages like
I noticed that the server actions run on the same URL as the page that's calling them, for example the action inside the deals page has this url
If a logged out user tries to access any page aside from the login page they are redirected
if a normal user tries to access pages under
/admin they are redirected to their user portalIf an admin tries to access pages under
/admin/notmyorg they are redirected to their organization's admin panelInside my pages like
/admin/myorg/users and /admin/myorg/deals I have server actions to mutate dataI noticed that the server actions run on the same URL as the page that's calling them, for example the action inside the deals page has this url
/admin/myorg/deals?rsc=W78UG-asdf2123F so I thought maybe I could remove the authorization check inside my server action since that check does the same thing as the one inside my middleware but I am not sure if I am missing something1 Reply
@Saltwater Crocodile Hi, I have a middleware in nextjs that authorizes users, and redirects them to the correct page if they try to access unauthorized pages.
If a logged out user tries to access any page aside from the login page they are redirected
if a normal user tries to access pages under `/admin` they are redirected to their user portal
If an admin tries to access pages under `/admin/notmyorg` they are redirected to their organization's admin panel
Inside my pages like `/admin/myorg/users` and `/admin/myorg/deals` I have server actions to mutate data
I noticed that the server actions run on the same URL as the page that's calling them, for example the action inside the deals page has this url `/admin/myorg/deals?rsc=W78UG-asdf2123F` so I thought maybe I could remove the authorization check inside my server action since that check does the same thing as the one inside my middleware but I am not sure if I am missing something
you are right: move the permission check to the server action as well. Technically it’s just a normal endpoint that you can call independently of the middleware and auth status. So secure it. Your middleware alr does a bit, but making it secure in the server action makes still sense tho